[{"data":1,"prerenderedAt":976},["ShallowReactive",2],{"navigation_docs":3,"-guides-worker-kit":270,"-guides-worker-kit-surround":971},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":272,"body":273,"description":964,"extension":965,"links":966,"meta":967,"navigation":968,"path":108,"seo":969,"stem":109,"__hash__":970},"docs\u002F3.guides\u002F13.worker-kit.md","Build a worker Kit",{"type":274,"value":275,"toc":955},"minimark",[276,286,289,294,324,328,335,376,383,387,397,672,675,735,739,797,808,812,821,863,871,892,895,899,915,925,940,944,951],[277,278,279,280,285],"p",{},"A ",[281,282,284],"a",{"href":283},"\u002Freference\u002Fconfiguration\u002Frepos#kits","Kit"," is an image that carries its\nown sandbox policy: which hosts its workload may reach, which credentials it\nholds, and its limits. Kraft runs a Kit you build for it. Docker's published\nKits require capabilities Kraft does not enforce, so Kraft refuses them.",[277,287,288],{},"This guide builds a Kit for Claude workers, pushes it to your registry, and\npoints a repository at it. Kraft publishes no worker image of its own.",[290,291,293],"h2",{"id":292},"before-you-start","Before you start",[295,296,297,310,321],"ul",{},[298,299,300,301,305,306,309],"li",{},"Docker with BuildKit (",[302,303,304],"code",{},"docker buildx","), logged in to a registry you can\npush to. Replace ",[302,307,308],{},"registry.example.com\u002Facme"," below with yours.",[298,311,312,313,316,317,320],{},"The machine that runs Kraft logged in to the same registry: Kraft reads\nthe Kit with that machine's ",[302,314,315],{},"docker manifest inspect"," and pulls it with\nits ",[302,318,319],{},"docker run",".",[298,322,323],{},"An Anthropic API key in the Kraft daemon's environment.",[290,325,327],{"id":326},"_1-write-the-image","1. Write the image",[277,329,330,331,334],{},"The image needs the platform floor and the agent CLI, and no agent\n",[302,332,333],{},"Entrypoint",": Kraft keeps the image's entrypoint and replaces its command\nwith the one the harness file builds, so an entrypoint that is the agent\nitself runs the agent twice.",[336,337,342],"pre",{"className":338,"code":339,"language":340,"meta":341,"style":341},"language-dockerfile shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","FROM docker.io\u002Flibrary\u002Fnode:22-slim\nRUN apt-get update \\\n && apt-get install -y --no-install-recommends bash ca-certificates curl git \\\n && rm -rf \u002Fvar\u002Flib\u002Fapt\u002Flists\u002F*\nRUN npm install -g @anthropic-ai\u002Fclaude-code\n","dockerfile","",[302,343,344,352,358,364,370],{"__ignoreMap":341},[345,346,349],"span",{"class":347,"line":348},"line",1,[345,350,351],{},"FROM docker.io\u002Flibrary\u002Fnode:22-slim\n",[345,353,355],{"class":347,"line":354},2,[345,356,357],{},"RUN apt-get update \\\n",[345,359,361],{"class":347,"line":360},3,[345,362,363],{}," && apt-get install -y --no-install-recommends bash ca-certificates curl git \\\n",[345,365,367],{"class":347,"line":366},4,[345,368,369],{}," && rm -rf \u002Fvar\u002Flib\u002Fapt\u002Flists\u002F*\n",[345,371,373],{"class":347,"line":372},5,[345,374,375],{},"RUN npm install -g @anthropic-ai\u002Fclaude-code\n",[277,377,378,379,382],{},"Save it as ",[302,380,381],{},"Dockerfile",". Kraft bind-mounts each session's result file on\nits own, so the worker writes it in place; a tool that replaced it by\nrenaming a new file over it would fail. The Claude CLI writes it in place.",[290,384,386],{"id":385},"_2-write-the-descriptor","2. Write the descriptor",[277,388,389,390,393,394,396],{},"Save this as ",[302,391,392],{},"kraft-worker-claude.yaml"," beside the ",[302,395,381],{},":",[336,398,402],{"className":399,"code":400,"language":401,"meta":341,"style":341},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","# syntax=docker\u002Fsandbox-kit:3\nschemaVersion: \"3\"\nkind: workload\ndisplayName: Kraft claude worker\ndockerfile: Dockerfile\ncapabilities:\n  - type: com.docker.sandbox\u002Fnetwork-policy@1\n    config:\n      runtime:\n        allow: [api.anthropic.com, statsig.anthropic.com]\n  - type: com.docker.sandbox\u002Fcredential@1\n    config:\n      service: anthropic\n      phase: runtime\n      apiKey:\n        name: ANTHROPIC_API_KEY\n        proxyManaged: true\n        inject:\n          - {domain: api.anthropic.com, header: x-api-key}\n  - type: com.docker.sandbox\u002Fresources@1\n    config: {cpu: 2, memory: 2gib}\n","yaml",[302,403,404,410,429,439,449,458,467,481,489,497,520,532,539,550,561,569,580,592,600,630,642],{"__ignoreMap":341},[345,405,406],{"class":347,"line":348},[345,407,409],{"class":408},"sHwdD","# syntax=docker\u002Fsandbox-kit:3\n",[345,411,412,416,419,422,426],{"class":347,"line":354},[345,413,415],{"class":414},"swJcz","schemaVersion",[345,417,396],{"class":418},"sMK4o",[345,420,421],{"class":418}," \"",[345,423,425],{"class":424},"sfazB","3",[345,427,428],{"class":418},"\"\n",[345,430,431,434,436],{"class":347,"line":360},[345,432,433],{"class":414},"kind",[345,435,396],{"class":418},[345,437,438],{"class":424}," workload\n",[345,440,441,444,446],{"class":347,"line":366},[345,442,443],{"class":414},"displayName",[345,445,396],{"class":418},[345,447,448],{"class":424}," Kraft claude worker\n",[345,450,451,453,455],{"class":347,"line":372},[345,452,340],{"class":414},[345,454,396],{"class":418},[345,456,457],{"class":424}," Dockerfile\n",[345,459,461,464],{"class":347,"line":460},6,[345,462,463],{"class":414},"capabilities",[345,465,466],{"class":418},":\n",[345,468,470,473,476,478],{"class":347,"line":469},7,[345,471,472],{"class":418},"  -",[345,474,475],{"class":414}," type",[345,477,396],{"class":418},[345,479,480],{"class":424}," com.docker.sandbox\u002Fnetwork-policy@1\n",[345,482,484,487],{"class":347,"line":483},8,[345,485,486],{"class":414},"    config",[345,488,466],{"class":418},[345,490,492,495],{"class":347,"line":491},9,[345,493,494],{"class":414},"      runtime",[345,496,466],{"class":418},[345,498,500,503,505,508,511,514,517],{"class":347,"line":499},10,[345,501,502],{"class":414},"        allow",[345,504,396],{"class":418},[345,506,507],{"class":418}," [",[345,509,510],{"class":424},"api.anthropic.com",[345,512,513],{"class":418},",",[345,515,516],{"class":424}," statsig.anthropic.com",[345,518,519],{"class":418},"]\n",[345,521,523,525,527,529],{"class":347,"line":522},11,[345,524,472],{"class":418},[345,526,475],{"class":414},[345,528,396],{"class":418},[345,530,531],{"class":424}," com.docker.sandbox\u002Fcredential@1\n",[345,533,535,537],{"class":347,"line":534},12,[345,536,486],{"class":414},[345,538,466],{"class":418},[345,540,542,545,547],{"class":347,"line":541},13,[345,543,544],{"class":414},"      service",[345,546,396],{"class":418},[345,548,549],{"class":424}," anthropic\n",[345,551,553,556,558],{"class":347,"line":552},14,[345,554,555],{"class":414},"      phase",[345,557,396],{"class":418},[345,559,560],{"class":424}," runtime\n",[345,562,564,567],{"class":347,"line":563},15,[345,565,566],{"class":414},"      apiKey",[345,568,466],{"class":418},[345,570,572,575,577],{"class":347,"line":571},16,[345,573,574],{"class":414},"        name",[345,576,396],{"class":418},[345,578,579],{"class":424}," ANTHROPIC_API_KEY\n",[345,581,583,586,588],{"class":347,"line":582},17,[345,584,585],{"class":414},"        proxyManaged",[345,587,396],{"class":418},[345,589,591],{"class":590},"sfNiH"," true\n",[345,593,595,598],{"class":347,"line":594},18,[345,596,597],{"class":414},"        inject",[345,599,466],{"class":418},[345,601,603,606,609,612,614,617,619,622,624,627],{"class":347,"line":602},19,[345,604,605],{"class":418},"          -",[345,607,608],{"class":418}," {",[345,610,611],{"class":414},"domain",[345,613,396],{"class":418},[345,615,616],{"class":424}," api.anthropic.com",[345,618,513],{"class":418},[345,620,621],{"class":414}," header",[345,623,396],{"class":418},[345,625,626],{"class":424}," x-api-key",[345,628,629],{"class":418},"}\n",[345,631,633,635,637,639],{"class":347,"line":632},20,[345,634,472],{"class":418},[345,636,475],{"class":414},[345,638,396],{"class":418},[345,640,641],{"class":424}," com.docker.sandbox\u002Fresources@1\n",[345,643,645,647,649,651,654,656,660,662,665,667,670],{"class":347,"line":644},21,[345,646,486],{"class":414},[345,648,396],{"class":418},[345,650,608],{"class":418},[345,652,653],{"class":414},"cpu",[345,655,396],{"class":418},[345,657,659],{"class":658},"sbssI"," 2",[345,661,513],{"class":418},[345,663,664],{"class":414}," memory",[345,666,396],{"class":418},[345,668,669],{"class":424}," 2gib",[345,671,629],{"class":418},[277,673,674],{},"What each capability becomes in Kraft:",[295,676,677,704,727],{},[298,678,679,685,686,688,689,692,693,696,697,700,701,703],{},[680,681,682],"strong",{},[302,683,684],{},"network-policy@1",": the sessions reach ",[302,687,510],{}," and\n",[302,690,691],{},"statsig.anthropic.com"," and nothing else. There is no ",[302,694,695],{},"install"," phase, so\nthe repository's ",[302,698,699],{},"setup_command"," reaches nothing: build what setup needs\ninto the image, or add an ",[302,702,695],{}," allow list. The Claude harness's own\nhosts are not added under a Kit, so a Kit for Claude lists them itself.",[298,705,706,711,712,715,716,719,720,722,723,726],{},[680,707,708],{},[302,709,710],{},"credential@1",": the container holds ",[302,713,714],{},"ANTHROPIC_API_KEY"," only as a\nsentinel, and Kraft's egress proxy puts the real key in ",[302,717,718],{},"x-api-key"," on its\nway to ",[302,721,510],{},". The value comes from the daemon variable you\nbind to the ",[302,724,725],{},"anthropic"," service in step 4.",[298,728,729,734],{},[680,730,731],{},[302,732,733],{},"resources@1",": two CPUs and a 2 GiB memory limit on every session.",[290,736,738],{"id":737},"_3-build-push-and-pin-it","3. Build, push and pin it",[336,740,744],{"className":741,"code":742,"language":743,"meta":341,"style":341},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","docker buildx build -f kraft-worker-claude.yaml \\\n  -t registry.example.com\u002Facme\u002Fkraft-worker-claude:1 --push .\ndocker buildx imagetools inspect registry.example.com\u002Facme\u002Fkraft-worker-claude:1\n","bash",[302,745,746,768,782],{"__ignoreMap":341},[345,747,748,752,755,758,761,764],{"class":347,"line":348},[345,749,751],{"class":750},"sBMFI","docker",[345,753,754],{"class":424}," buildx",[345,756,757],{"class":424}," build",[345,759,760],{"class":424}," -f",[345,762,763],{"class":424}," kraft-worker-claude.yaml",[345,765,767],{"class":766},"sTEyZ"," \\\n",[345,769,770,773,776,779],{"class":347,"line":354},[345,771,772],{"class":424},"  -t",[345,774,775],{"class":424}," registry.example.com\u002Facme\u002Fkraft-worker-claude:1",[345,777,778],{"class":424}," --push",[345,780,781],{"class":424}," .\n",[345,783,784,786,788,791,794],{"class":347,"line":360},[345,785,751],{"class":750},[345,787,754],{"class":424},[345,789,790],{"class":424}," imagetools",[345,792,793],{"class":424}," inspect",[345,795,796],{"class":424}," registry.example.com\u002Facme\u002Fkraft-worker-claude:1\n",[277,798,799,800,803,804,807],{},"The ",[302,801,802],{},"# syntax=docker\u002Fsandbox-kit:3"," line makes BuildKit build it with the Kit\nfrontend, which puts the descriptor on the image's manifest. The second\ncommand prints the digest (",[302,805,806],{},"Digest: sha256:...","). Pin the Kit by it: a tag\ncould name a different Kit tomorrow, and Kraft refuses one.",[290,809,811],{"id":810},"_4-point-a-repository-at-it","4. Point a repository at it",[277,813,814,815,820],{},"In ",[281,816,817],{"href":283},[302,818,819],{},"repos.yaml",", under the\nrepository's entry:",[336,822,824],{"className":399,"code":823,"language":401,"meta":341,"style":341},"sandbox:\n  kind: kit\n  runtime: docker\n  kit: registry.example.com\u002Facme\u002Fkraft-worker-claude:1@sha256:\u003Cthe digest>\n",[302,825,826,833,843,853],{"__ignoreMap":341},[345,827,828,831],{"class":347,"line":348},[345,829,830],{"class":414},"sandbox",[345,832,466],{"class":418},[345,834,835,838,840],{"class":347,"line":354},[345,836,837],{"class":414},"  kind",[345,839,396],{"class":418},[345,841,842],{"class":424}," kit\n",[345,844,845,848,850],{"class":347,"line":360},[345,846,847],{"class":414},"  runtime",[345,849,396],{"class":418},[345,851,852],{"class":424}," docker\n",[345,854,855,858,860],{"class":347,"line":366},[345,856,857],{"class":414},"  kit",[345,859,396],{"class":418},[345,861,862],{"class":424}," registry.example.com\u002Facme\u002Fkraft-worker-claude:1@sha256:\u003Cthe digest>\n",[277,864,814,865,870],{},[281,866,867],{"href":177},[302,868,869],{},"sandbox.yaml",", bind the credential's\nservice to the daemon variable holding the key:",[336,872,874],{"className":399,"code":873,"language":401,"meta":341,"style":341},"credentials:\n  anthropic: ANTHROPIC_API_KEY\n",[302,875,876,883],{"__ignoreMap":341},[345,877,878,881],{"class":347,"line":348},[345,879,880],{"class":414},"credentials",[345,882,466],{"class":418},[345,884,885,888,890],{"class":347,"line":354},[345,886,887],{"class":414},"  anthropic",[345,889,396],{"class":418},[345,891,579],{"class":424},[277,893,894],{},"The right-hand side is a variable in the Kraft daemon's environment; it can\nhave any name.",[290,896,898],{"id":897},"_5-check-it","5. Check it",[336,900,902],{"className":741,"code":901,"language":743,"meta":341,"style":341},"kraft admin doctor\n",[302,903,904],{"__ignoreMap":341},[345,905,906,909,912],{"class":347,"line":348},[345,907,908],{"class":750},"kraft",[345,910,911],{"class":424}," admin",[345,913,914],{"class":424}," doctor\n",[277,916,917,918,920,921,924],{},"The repository's ",[302,919,830],{}," row reads and checks the Kit. A ",[302,922,923],{},"kit hosts"," row\nwarning about Amp, Codex or Gemini hosts is expected: this Kit is for Claude, and\nsessions of other harnesses under it are refused their hosts.",[277,926,927,928,931,932,935,936,320],{},"File a work item on the repository. Its first task records a\n",[302,929,930],{},"sandbox_kit_resolved"," event: ",[302,933,934],{},"kraft view events ID --type sandbox_kit_resolved",".\nIf the item stops instead, see\n",[281,937,939],{"href":938},"\u002Fget-started\u002Ftroubleshooting#a-kit-is-refused","A Kit is refused",[290,941,943],{"id":942},"changing-the-kit","Changing the Kit",[277,945,946,947,950],{},"A rebuilt Kit has a new digest. Put the new digest in ",[302,948,949],{},"kit:",". An item filed\nbefore the change keeps the sandbox it was filed with.",[952,953,954],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sfNiH, html code.shiki .sfNiH{--shiki-light:#FF5370;--shiki-default:#FF9CAC;--shiki-dark:#FF9CAC}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}",{"title":341,"searchDepth":354,"depth":354,"links":956},[957,958,959,960,961,962,963],{"id":292,"depth":354,"text":293},{"id":326,"depth":354,"text":327},{"id":385,"depth":354,"text":386},{"id":737,"depth":354,"text":738},{"id":810,"depth":354,"text":811},{"id":897,"depth":354,"text":898},{"id":942,"depth":354,"text":943},"Build a Docker Sandbox Kit for Kraft's Claude workers, push it to your registry, and run a repository's sandbox from it, pinned by digest.","md",null,{},{"title":107},{"title":272,"description":964},"CazvrBp24PUOjo9MOZFcCQKo_9uDGAlW331T5SHyHPs",[972,974],{"title":103,"path":104,"stem":105,"description":973,"children":-1},"Back up Kraft's database, find its logs, reclaim worktree disk space, run two instances side by side, and run Kraft as a service.",{"title":10,"path":112,"stem":116,"description":975,"children":-1},"Look-up pages for the CLI, configuration files, chain nodes, permissions, harnesses, triggers, the HTTP API, MCP tools, environment variables, and events.",1790824507606]